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Recently some alternatives of the measurement device independent quantum key 
distribution(MDI-QKD) based on the single-photon Bell state measurement (SBSM) have 
been proposed. Although these alternatives are not precisely as secure as MDI-QKD, they possess 
the advantage of high key rate of traditional BB84-like protocol and avoid the technical complexity 
of two-photon interference required in the MDI-QKD. However, the setups of these proposed 
schemes are rather complicated compared to commonly used BB84 systems. Here we propose a 
simple implementation of SBSM-based QKD which is directly built on the existing realization 
of BB84 QKD. Our proposal exhibits the hidden connection between SBSM-based QKD and 
traditional phase-coding QKD protocols. This finding discloses the physics behind these two 
different types of QKD protocols. In addition, we experimentally demonstrate the feasibility of our 
protocol. 
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Introduction. Quantum key distribution(QKD) is the first quantum technology that comes into real life. It 
is aimed at sharing unconditionally secure information between two communication parties Alice and Bob even in 
the presence of a malicious eavesdropper Eve, which is impossible for classical strategy. Since its first proposal in 
1984(11, the theoretical analysis and practical implementation of QKD has been universally and deeply studied (3- 
M- Recently some significant improvements on the security of QKD’s practical implementation are proposed. For 
example, all the detector related loop-holes can be removed by the measurement device independent QKD (MDI- 
QKD) protocol pIBi fl^. MDI-QKD protocol has attracted worldwide attention and has been widely studied both in 
theory and experimental implementations [2314^. And even loop-holes in the state preparation stage for 

MDI-QKD can be removed in qubit case[^. 

However, an implementation of MDI-QKD protocol requires the interference of photons from two individual lasers, 
which is still relatively complicated for present technology and leads to a substantial experimental decrease in the 
key rate in comparison with the BB84 protocol. For alleviating this side effect, there are some alternative schemes 
proposed recently pbl - l^ . Instead of utilizing the two-photon interference, these schemes utilize a single-photon Bell 
state measurement setup which avoids the difficulty of two-photon interference and possess the property of high 
key production of the traditional QKD scheme. In these schemes (we call them SBSM-QKD for abbreviation, since 
they are based on single-photon Bell state measurement), Alice first encodes a photon in a two-dimension space, 
polarization for example. Then Alice sends the photon to Bob who further encodes the photon in another degree of 
freedom, such as spatial path and time bin. In the end. Bob measures the incoming photon with an untrusted Bell 
state measurement setup. 

In all previous implementations of SBSM-QKD, the polarization encoding and path encoding are both conducted. 
Thus its implementation is more complicated than a BB84’s. In this article a simple realization of the idea of SBSM- 
QKD based on the phase encoding QKD setup is given. In our scheme, only time-bin and path encoding are needed. 
Hence it is very concise and quite similar as conventional phase coding BB84 systems. At last, by considering that 
only one Bell state projection will suffice the security of MDI-QKD or SBSM-QKD, it is found that a SBSM-QKD 
can be even realized with a setup which is totally identical to that of phase encoding BB84 system without any 
modification. 

Before proceeding to our proposal, one must note that the fact that as a simpler and more practical alternative 
to the previous proposals, SBSM-QKD is not strictly as secure as MDI-QKD, because assumptions on measurement 
devices must be made in SBSM-QKD [^. However, SBSM-QKD may be more secure in some sense, compared 
to traditional QKD protocols, like BB84. For example, the security of SBSM-QKD can be proved even under the 
assumption that Eve can decide the output of the BSM device [26|. Thus, as a simple way to implement SBSM-QKD, 
our proposal is also not a MDI-secure one. The merit of our scheme is that one may achieve it even using the existing 
phase-coding QKD systems. In the next section, we give our scheme and prove our scheme is equivalent to the one 
proposed in Ref. na mathematically. 

A simple implementation. In a SBSM-QKD, the most essential part is the measurement of four Bell states: 


l^)^ = ^(|00)±|ll)) 
|vi/)± = T(|oi)±|io)) 


( 1 ) 


or any other states combination of equivalent mathematical form. 

Here we use the phase encoding QKD setup as shown in Fig.l to show how Alice and Bob to encode and conduct 
the Bell state measurement (BSM). For simplicity, we assume Alice is equipped with an ideal single photon source. In 
the figure, the shaded area is untrusted area while the other is trusted and characterized. To realize a SBSM-QKD, 
Alice first chooses the encoding phase a randomly from the set {0,7r/2, tt, 37r/2} and apply it to her single photon. 
The phase is introduced only on the long arm I while no modulator is placed on the short arm s. This is essentially 
an encoding on the spatial basis of Alice. The photon state leaving Alice’s region has the form: 


!</.) = T(|z)e- + |5)). (2) 

In Bob’s area, the photon is further encoded with his spatial basis, that is, path L and S. Similar to Alice’s operation, 
an additional phase /3 chosen from {0,7r/2, tt, 37r/2} is introduced in the long arm L. Since Alice and Bob encode 
independently, it is trivial to write the photon state after encoding operations: 




+ S 


x/2 


{\L)e^^ + | 5 )). 


(3) 


Obviously, the encoding operations performed by Alice and bob are totally equivalent to the encoding process in 
Ref. [ 23 . One should also note that this encoding process is just the same as the experiment made in Ref, . 


3 


Alice 



FIG. 1. Schematic of the modified phase encoding protocol for SBSM-QKD. BS: beamsplitter (fiber). PM: phase modulator. 
SPD: single photon detector. The difference between our protocol and the original phase encoding is the optical switches in 
Bob’s short arm which are designed to select different paths at different timing window, a detection event at the time \IS) or 
\sL) indicates the projection onto |T)^ = -^{\IL) ± \sS)) and a detection event at the time \IL) indicates the projection onto 

1$)^ = ^ 1'®^))- The ’+’ or depends on which detector signals. 


TABLE I. The detection events with respect to different phase application by Alice and Bob, and the corresponding Bell states. 
The photon traveling \IS) or |sL) arrive at tO while the photon traveling \IL) or the delayed \sS) arrives at tl. 
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Next the photon is sent to the BSM device for measurement, which is the shaded area in the figure. We will show 
the BSM in our scheme is also equivalent to Refp^’s. 

The Eq.(j3]) can be expanded into the following: 

l<A) = T(^(|;i:)e*(«+/5) + |55)) + + \sL)e^^)). (4) 

With different combination of a and /3 chosen from the set {0,7r/2 , tt, 37 r/2}, it can be seen that in Eq.(|l]) the former 
half in the bracket, + \sS))/^/2^ is virtually the |^)T in Eq.([T|) and the latter half, (|/5')e*^ + \sL)e^^)/\/2^ 

is the |^)T in Eq.([T]). In the original phase encoding protocol, only 1^)^ is measured for generating keys, which is 
virtually a partial BSM. To obtain a complete BSM, it is necessary to measure all of the four Bell states. For this 
purpose, a path selection structure is added to the short arm in Bob’s area to delay the \sS), as shown in the figure. 
The length of path a guarantees that \sL) and \IS) interfere at the beam-splitter in BSM device and can be measured 
at time tO by single detectors, while the length of b guarantees that \IL) and the delayed \sS) also interfere at the 
beam-splitter in BSM device and can be measured at a later time tl. 

In summary, our SBSM-QKD protocol works as follows: 

1 . Alice encodes the photon with his spatial basis and a phase modulator. 

2 . Bob encodes the photon with his spatial basis and a phase modulator. 
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FIG. 2. (color online). Experimental schematic diagram. BS: beamsplitter(fiber). PM: phase modulator. Dl, D2: single 
photon detector. ATT: attenuator. IM: intensity modulator. In order to simplify the experiment process, we replace the 
optical switch in Fig. (T] which is intended for choosing paths of the photon, with a beam splitter. Furthermore, for increasing 
the stability of the system, we adopt the Faraday-Michelson phase-coding system. 


3. The complete Bell measurement is performed. For this purpose, Bob operates the optical switches to select from 

paths a and b in the following way. At the time \sS) arrives, he selects the path b. Afterwards, when \IS) arrives, 
he selects the path a. After the measurement of he selects again path b to conduct the measurement of 

i$)±. 

4. Alice and Bob distill secure keys from the detection results where their phases are in the same basis of the 
original phase encoding protocol, that is, \a — P\ = 0 or tt. 

In the protocol, a detection event at the time tO indicates the projection onto and a detection event at the 

time tl indicates the projection onto |4>)^. The or depends on which detector signals. The specific outcomes 
are shown in Table I. One can see that this table is totally equivalent to the table I in Ref.ji^ easily. Thus even 
the BSM device in the shaded area in the Fig.l is also equivalent to the one in Ref.jl^. Therefore, our scheme is an 
implementation of SBSM-QKD protocol. 

Experimental Demonstration. In the following, we experimentally demonstrate the feasibility of SBSM-QKD 
protocol. Our experiment is mainly based on a Faraday-Michelson phase-encoding QKD system, in which the po¬ 
larization disturbances caused by quantum channel and optical devices can be auto-compensated Q. Thus, keeping 
steady and high interference fringe visibility is easy in this QKD system. 

The experiment schematic is shown as Fig. [2l In this experiment, we use a laser emitting 1550nm weak coherent 
pulses. The entire setup is synchronically working at a repetition rate of IMHz. The intensities of signal, decoy, and 
vacuum states are fi = 0.6, v = 0.2, 0, respectively, and their pulse numbers ratio is 6:2:1. Single-photon detectors 
in our experiment are Superconducting Nanowire Single Photon Detector (SNSPD), whose dark count probability is 
approximately 5 x 10“^/^ate and the detection efficiency is about 15.3%. At each experimental distance we collected 
10^ signal pulses . The loss coefficient of the channel is 0.2 dB/km and the insertion loss is 5 dB on Bob. In addition, 
secret key rate is estimated according to finite-key analysis proposed in Ref.js^ which adopted the Chernoff bound. 
Then we compare the experimental result with theoretically expected result in Fig. [3l Our results clearly shows that 
even with a realistic finite size, say 10^, it remains possible to achieve secure SBSM-QKD at the distances as long as 
175km. 

Conclusion. We propose a simple realization of the recently proposed idea of SBSM-QKD, basing on the phase 
encoding structure while taking a tiny modification. Furthermore, we experimentally demonstrate the feasibility of 
this protocol. Then with finite-key analysis, we reached a secure distance of 175 km, and the Secret key rate is 
3.655 X /pulse. 

A complete Bell state measurement is performed in the protocol, which means that the protocol bears the same 
mathematical description and security level with the other SBSM-QKD schemes [2^, In this article, we have 
a comment on those papers. According to theoretical security analysis on the MDI-QKD, it is known that the 
measurement of partial Bell state possesses the same security property with the complete Bell state measurement [Hi 
[ 2 O, [2l|. In Ref, jig . it is proved that if the BSM device can only distinguish one Bell state, the security of MDIQKD 
will remain the same. Thus, it’s very reasonable to conjecture that partial BSM will not affect the security of SBSM- 
QKD protocol. As mentioned in the second section, if we remove the path b of the BSM device in Fig.l, this schematic 
is just a phase coding BB84 system in Ref. M , which is a partial BSM process. 

Hence the original phase encoding, which is essentially a partial Bell state measurement, is equivalently secure to 
the modified version in this article. Or rather, the original phase encoding scheme as implemented in Ref.[lJ, where 
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FIG. 3. (color online). Tlieoretical(lines) and experimental(crosses) key rates in logarithmic scale with respect to the distance. 
The solid lines correspond to the key rate calculated with 10^ signal pulses. In comparison, the dotted line represents the key 
rate with infinite signals. For this two curves we consider the following parameters: security bound £ = 10~^, probability that 
a photon hit the erroneous detector Cdetector = 0.015 and correction efficiency / = 1.16. Other parameters, for instance, the 
detection efficiency, are the same as experimental parameters. Five crosses represents experimental key rates. At 175 km, the 
secret key rate is 3.655 x /pulse. 


Bob modulates four phase-values, is virtually a SBSM-QKD. 
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